CMS
For developersFor clients
How it worksPricingFAQDocs
Log inStart free
For developersFor clientsHow it worksPricingFAQDocsLog inStart free

Security

Built so a leak stays small.

Last updated 29 September 2026. Tusk CMS is operated by Brand Growth Advisory Pty Ltd (ABN 55 699 084 396), Queensland, Australia. This page describes how the product works, not a certification. Found a problem? Email hello@tuskcms.com.

Tusk never holds your hosting

Tusk stores the words, photos and downloads your clients edit, along with the accounts and project notes you add. Your website stays in your own repository, on your own host. A publish reaches the live site through a deploy hook you created in your own host, or through a build that pulls the content feed. Nothing of Tusk runs between a visitor and your site. With a deploy hook, the hook’s link is all Tusk holds of your host; only if you choose to have Tusk deploy for you does it hold a host API token, the one you give it, which you can remove at any time.

Access tokens you approve

When you connect a site with your AI tool, you approve the token on a screen that names the site and the actions it is for. It never holds your password and cannot touch your code or hosting on its own. Every paired token expires by itself (30 days by default), you get an email the moment one is approved, and you can revoke any token instantly from the dashboard, under Studio settings.

Secrets encrypted at rest

The build token, deploy hook, any host API token and any webhook secret are encrypted in the database and shown only masked. The build token is written straight into your git-ignored .env by the tooling and is never shown to the AI agent. Tusk’s own guides and pages contain no credential of any kind.

Isolation between studios and sites

Every studio sees only its own sites, content and clients, enforced on every request, not just in the interface. A client logs in to Tusk only, sees only the fields marked editable on their own site, and never gets access to your repository, your host or your AI tools.

The public content feed

A site’s content feed is token-less only when you turn it on, and then it serves only that site’s published content and the images those pages reference. Invoices, client files and drafts are never exposed. It is off by default.

Payments

Card details are handled by Stripe and never touch Tusk’s servers. Tusk stores only a Stripe customer reference and your plan status.

Data and backups

Content and account data live in a managed Postgres database (Neon) with uploads in Vercel Blob storage, hosted in the eastern United States (Neon us-east-1 and Vercel’s Washington, D.C. region). The database is backed up by the managed provider. If you close a studio you can export every site first, and closed studios are purged after a grace period.

Reporting a vulnerability

Email hello@tuskcms.com with the details and steps to reproduce. We’ll acknowledge, investigate, and keep you posted. Please don’t run automated scans against production or access data that isn’t yours.

Privacy · Terms

CMS
For developersFor clientsPricingDocsFAQAffiliatesLog inSupport
Built withLovablev0BoltReplitClaude CodeCodexCursorWindsurfNext.jsAstroFramerHTML
Tusk CMS · an ORYX productSecurityPrivacyTerms
Powered by ORYX